Record summary

CVE-2022-0230 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Better WordPress Google XML Sitemaps (support Sitemap Index, Multi-site and Google News)

CVE List1.4.1 to ≤ 1.4.1affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-0230Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 595 B

GitHub

PoC details
GitHubCVE-2022-0230Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 595 B

GitHub

PoC details

References

2